Why your server is trapped on a 2 Mbps Plex Relay and how to bypass CGNAT for full-quality direct streams
Ready to break free from CGNAT and restore full-bitrate Direct Play on your Plex server?
Few things in homelab setups are as infuriating as the yellow triangle next to Remote Access in Plex.
You spend days organizing your library. You set up a solid machine, wire it directly to gigabit ethernet, and enable Remote Access in the settings. Inside your home network, everything plays like a dream. 4K HDR files start instantly, skipping tracks takes zero seconds, and audio plays uncompressed.
Then you leave the house.
You open the Plex app on your phone, laptop, or an Airbnb TV. Instead of the clean green status light, you see a small warning icon and the word **Indirect**.
You press play anyway. Your pristine high-bitrate video instantly buffers, the server CPU spins up to 100% trying to transcode, and the playback quality looks like an early 2000s web video. If you check the stream playback info, it tells you everything: the stream is locked to an exact limit of 1 Mbps or 2 Mbps.
You go home, restart your server, toggle UPnP, manually forward port 32400 in your router, and reboot your modem. For about ten seconds, Plex Settings lights up green—and then flips right back to red: *"Not available outside your network."*
The reason this happens has almost nothing to do with your Plex configuration. You are running headfirst into Carrier-Grade NAT (CGNAT), and using the wrong kind of VPN will only make the indirect connection worse.
### The Real Culprit: Why Your Router Port Forwards Do Nothing
In the early days of home broadband, your internet provider handed your modem a dedicated public IPv4 address. When you opened port 32400 on your home router, incoming requests from remote Plex clients knew exactly which physical front door to knock on.
Today, IPv4 addresses are scarce. To stretch their allocation, most modern fiber, cable, 5G home internet, and cellular providers place residential customers behind Carrier-Grade NAT (CGNAT).
In simple terms, your router does not have its own public IP. Instead, your router is sitting inside a giant private subnetwork managed by your ISP, sharing a single public gateway IP with hundreds of your neighbors.
When you set up a port forward on your personal router, you are only unlocking an internal bedroom door inside a house whose main entrance gate is permanently locked by your provider. Remote Plex clients trying to reach your server from the outside internet cannot find a direct route to your machine.
When Plex detects that an outside client cannot establish a direct handshake with your server, it refuses to drop the connection entirely. Instead, it engages a fallback mechanism called **Plex Relay**.
Plex Relay routes your entire video stream through third-party proxy servers hosted by Plex. Because bandwidth costs money, Plex enforces a hard limit: standard users are throttled to 1 Mbps, while Plex Pass subscribers are capped at 2 Mbps. That is why your 50 Mbps 4K stream gets violently transcoded into a blurry, stuttering mess.
### Why Standard Commercial VPNs Make Plex Remote Access Worse
Once people discover CGNAT is the issue, their first instinct is to install whichever popular VPN they already use on their phone or laptop onto the Plex server.
Almost every time, that completely destroys remote access.
Most general consumer VPNs are designed exclusively for outbound privacy. They route your server's web traffic through a shared outbound IP behind their own massive firewall. Crucially, they do not give incoming traffic any path back in.
The moment you turn on a standard VPN on your media server:
- Your server's local IP routing gets scrambled, making it invisible to local players on your living room Apple TV or Nvidia Shield.
- The VPN blocks incoming handshake requests from Plex's remote servers because the VPN does not forward incoming ports.
- Plex either stays permanently locked in "Indirect" relay mode or disappears from your remote dashboard entirely.
To solve an indirect connection, you do not need generic encryption that hides your web browsing. You need a network tunnel that provides an accessible public ingress point that points directly back to your Plex port.
### What Actually Restores a Direct Connection
To eliminate the 2 Mbps relay cap and stream your library at full, uncompressed quality away from home, your connection setup has to fulfill three specific requirements:
**1. Clean Inbound Port Forwarding or Dedicated Static Routing**
The tunnel must provide an unblocked external port or a clean public IP that listens for incoming connection requests from Plex clients and tunnels them straight to your media server, completely ignoring your ISP’s CGNAT wall.
**2. High-Bandwidth, Unthrottled Uplink Capacity**
Streaming uncompressed 1080p and 4K media requires substantial upload throughput without artificial speed caps. The tunnel must handle sustained 20 to 80 Mbps video transfers without packet loss or jitter.
**3. Split Tunneling and Local Subnet Preservation**
The VPN client must allow your local home network (LAN) to bypass the tunnel. If a VPN forces all traffic through its interface, your TV in the living room will unnecessarily stream through the internet instead of communicating directly over your local switch.
### How ONLYDOGSVPN Fixes the Plex Indirect Error
This specific requirement—bypassing residential ISP barriers without compromising server routing—is where ONLYDOGSVPN provides a clean, workable solution.
Instead of bundling useless browser extensions and heavy bloatware that bogs down server background tasks, ONLYDOGSVPN focuses on direct, high-throughput routing designed to handle server workloads:
- **CGNAT Bypass:** Gives your server a clean, reachable tunnel address that establishes a direct external route, pulling Plex off the restricted 2 Mbps Relay network once and for all.
- **Unthrottled Upload Speeds:** Delivers raw, uninterrupted bandwidth so remote streams can run in original quality with Direct Play rather than forcing your server hardware to transcode.
- **Stable Long-Running Connections:** Built to maintain persistent connections 24/7 without random IP shifts or silent disconnects that knock your server offline mid-day.
- **Low CPU Footprint:** Runs lightweight modern protocols that consume negligible processor cycles, leaving your system resources entirely free for media indexing and hardware transcoding when needed.
### When You Should Not Buy This
Let's be completely candid about network mechanics: a VPN solves routing and CGNAT limitations; it cannot fix physical hardware deficits.
If your home broadband plan has an upload speed limit of 5 Mbps from your provider, no VPN can magically produce 30 Mbps of upload bandwidth for a remote 4K stream. Your remote streaming ceiling is always bounded by the actual physical speed of your home internet plan.
Similarly, if your Plex server is connected via an unstable, fluctuating 2.4 GHz Wi-Fi link on the other side of your house, your stream will buffer regardless of your network configuration. Media servers should always be wired via physical ethernet to your primary router or switch.
Only use ONLYDOGSVPN if your home upload speed is fast enough for your media bitrates, your local playback works properly, and your only roadblock is your ISP's CGNAT wall forcing remote streams through the 2 Mbps Plex Relay.
### How to Configure Direct Remote Access
Setting up your server for direct streaming takes only a few minutes once you have the connection active:
First, install and connect ONLYDOGSVPN on the host machine running your Plex Media Server (whether on Windows, Linux, or a dedicated server).
Second, configure split tunneling within the app or route your local subnet (`192.168.x.x` or `10.0.x.x`) outside the tunnel so devices on your home Wi-Fi continue streaming directly over your local network.
Third, open your Plex Web interface, navigate to **Settings > Server > Remote Access**, and click **Show Advanced**.
Check the box for **Manually specify public port**, enter the assigned port from your tunnel connection, and click **Apply**.
Once Plex verifies the handshake, the status indicator will shift to a solid green checkmark: *"Fully accessible outside your network."*
From that moment on, whenever you connect from an airport, a friend's house, or a mobile network, the "Indirect" badge disappears. Your remote streams connect directly to your server, streaming at full original resolution just as if you were sitting on your own couch.